How Diaspora killed itself before it even launched
jarinheit.posterous.com
jarinheit.posterous.com
I don't understand this "no way in hell I am signing a contract just to contribute to an open source project" sentiment. It is trivially easy to do (see Node.js's CLA which is an entirely electronic form,) and it gives the users all sorts of additional protections that traditional open source licenses can't otherwise provide, such as patent royalty protections.
The downside of these CLA agreements is that it allows the controllers of the project to re-release code under a less stringent license, and in some cases a commercial license. I can see someone becoming upset that code they worked on in a GPL project was later released as BSD, but that doesn't seem to be an issue with the OP.
All in all, the only reasonable take away here can be summarized in a sentence: "Diaspora may have a more limited uptake by corporations who are hesitant to open source proprietary additions to the software."
Certainly nothing to write a rant over.
The reality is that this "virality" you're talking about is a perfectly reasonable authorship protection. It allows groups that want to claim firm ownership of a project to release its source code without worrying about ending up competing with a fork.
We all know, at least ever since Github made it cool, that forks are a desirable property of open source development. But it wasn't always looked on that way and sometimes it in fact isn't desirable. Perfect example: a company that wants to make a living selling a product. We're all better off if they publish their source code, but if they do it with straight GPL, it's going to end up used against them in someone's web app.
This is neither here nor there with respect to Diaspora. They may have made some claim about exactly how "open" their "openness" is intended to be. But it's simply not fair to suggest that the AGPL is an egregious license. "ALL RIGHTS RESERVED" is an egregious license, and the most popular license in the world.
Also as far as the contract goes, it's only if you want to contribute code back to Diaspora project and have it become part of canonical codebase. There's nothing to prevent you from making those contributions available on your fork and have them remain open.
If you want to keep your code closed, then you're more than welcome to do that. Just honor the choice that others have made with their code.
This limit is perfectly in line with the Declaration of the Rights of Man and of the Citizen. I argue that anything that allow this limit to be crossed does not most efficiently promotes freedom.
Yes, permissive licences do not most efficiently promote freedom. (Don't get me wrong: they do promote freedom.)
Now the AGPL, because of its additional restriction, could be seen as less free. I think that technically, it is (it doesn't fully give you the right to private modifications). But the spirit is the same, applied to remote applications instead of distributed software.
[Condescending explanation] Among the four freedom, free software gives you freedom 1: the right to private modifications. Meaning, as long as you do not redistribute the software, you don't have to redistribute the source code. And if you do distribute a particular version of that software, only that version of the source code must be accessible. You can still conceal a private fork.
Now in the case of software executed remotely, or software as a service, Eben Moglen himself reckons there is a conflict of rights: because the client is effectively using the code, it should have access to the source code. And because the server do not actually distribute the software, it should have the right not to release anything.
You can't satisfy both rights at the same time. The GPL satisfies one (it is 100% compatible with privacy rights), and the AGPL satisfies the other (and makes itself incompatible with some privacy rights in the process). That's a pity, because before the rise of software as a service, the GPL was the ultimate freedom respecting licence. Now you have to choose between two compromises.
PS: Don't say "property" about software, if you can help it. It is a inaccurate analogy from the physical goods, which fail to convey the truth about knowledge. (Of course, software is pure knowledge.)
Specifically, I'm skeptical of the claim that if a client uses code, he or she deserves access to the source code. Sure, it's probably better to provide access to it, just like it's probably better to donate to charity, but I don't think either should be enforced by threat of violence (while it may sound silly initially, software license litigation boils down to a threat of violence).
To me, code in the public domain (or all code in a society with no legal protection for code) is perfect. That seems to me like purer freedom.
Lastly, when did I say "property" about software? I'm against legal protection for intellectual property when it comes to software. I agree that software is pure knowledge, every piece of software (that compiles/runs) is an algorithm (in fact, a number), and that writing a piece of software or coming up with an algorithm should give you no inherent ownership of it.
What you call "purer freedom" is actually negative freedom, which is about not forbidding. The GPL promotes positive freedom, which is about enabling. As we can see when we compare the GPL and permissive licences, the GPL is more effective at enabling everyone to look at the source code. For me, that's what counts. I don't care about how "pure" the freedom is, I just care about it's effectiveness.
Lastly, you said "Free software […] is incompatible with privacy and property rights". "Privacy" was appropriately used, but I think you tossed "property" without much thought, using its positive and undeniable aura.
How can this be a negative vs. positive freedom argument? Not distributing source code places restriction on the client, while forcing developers to distribute source code places restriction on the developers. Either way, if software usage is restricted at all, then someone's freedoms are going to be restricted. The only solution I see is for there to be no legal protection of software, period.
I used "property" to refer to the physical hard drive holding your data, as well as your house and land. Of course, many argue that privacy rights follow logically from property rights, so the distinction probably isn't necessary.
To exercise your right to free speech, the only reasonable way is to use the Internet. And you need to run computer code to do that. Similarly, to protect your privacy, the code you run (all of it) has to be trustworthy. And I say that to be trustworthy, the code must be free, at least for you. Conclusion: running free code (and only free code) is necessary to exercise some fundamental rights. Therefore, everyone deserve it.
The positive/negative freedom argument comes from the facts that (0) the four freedom are way more important than the freedom to proprietarize software, and (1) they conflict. If you want to preserve the greater freedoms, you have to sacrifice the lesser one. Now, people could be reasonable, and respect the four freedom even when they are allowed not to. But I think we can agree that many people aren't reasonable (the most famous example was X).
I now understand your usage of the word "property" was indeed legitimate.
You can build onto GPL for free without reciprocating. That's called freedom 1: the right to private modifications.
For me the technical "architecture" did it.
A rails-app, of all things, to serve as some sort of "superpeer" for what cries to be a P2P system? Really?
And their answer to their stated goal of "privacy aware, personally controlled" is to store the data not in one opaque box (facebook) but to distribute it over many opaque boxes, under the control of random people, without some sort of end-to-end encryption involved?
Really?
Sorry, but not only does real P2P technology exist, there are even free and mature implementations out there for most of the primitives that a distributed facebook would require. Why not plug together what's needed and invent what's missing?
We have mature DHT impls like Kademlia (edonkey), Chord, freenet. Look at the concept of Web-of-Trust and RSA/PGP for identity management in a distributed system. Look at jabber for messaging and presence.
Something is seriously, fundamentally wrong when your answer to "distributed system" comes out as "Rails".
No. P2P networks like freenet and edonkey already distribute content over many nodes, just with different goals and priorities. It would be possible to adapt these mechanisms to ensure that data you push to the network actually stays in the network for a reasonable period of client-downtime. I could think of various ways to achieve this technically (n-copies, caching superpeers, and each of your friends would naturally hold on a copy anyways).
One important bit to realize here is that the data volume is rather small because only meta-data (friends-graph, profile, wall, messages, etc.) needs to be handled in a truly distributed fashion.
Big chunks, such as images, could and should mostly remain on centralized services for the time being.
Another important thing to realize is, that the privacy in such a network could be made to be much better than on any remotely hosted solution because you can implement end-to-end encryption. All data on the network would naturally be transmitted and stored only in encrypted form. You would reveal chosen pieces to your friends by sharing the respective keys with them.
So Rails isn't a necessarily stupid idea for a social network consisting of people like me.
People like you (the end-user) aren't even supposed to install diaspora on their machines. Instead (if I understood them right) you are supposed to sign up on someone else's diaspora installation and generally trust all diaspora nodes in the network because your data travels freely between them.
Disclaimer: If this description is wrong then someone please correct me. There's some conflicting information about what diaspora is and what it wants to be.
Rails surely has its place in many applications. But for this one it just screams "We have no clue what we're doing" to me.
If reading a person's social network communication and local friend graph requires approximately the same effort as breaking into an individual mail server or sniffing SMTP traffic on a network node, and the criminal effort is approximately proportional to the number of persons to supervise, that's OK for 1.0 for me.
I don't know the details of the protocol between Diaspora instances. But I hope that if some foreign Diaspora instance wants to read my messages to my friends on my own Diaspora instance, then it has to supply some proof that one of its users is a friend of mine.
Their prototype leaves so many basic (and hard!) questions unanswered that, to me, their architecture smells less like a conscious decision and more like a strong case of: "If all you have is a hammer then everything starts to look like a thumb."
In all honesty it looks like a non-starter to me.
Sure, "just start hacking" is what everyone tells young startups to do, and that's what they apparently did.
But that approach doesn't work very well for building a distributed system where all the components absolutely must snap into one another if you don't want the whole thing to fall apart under stress. Much less if your stated goals include terms like "privacy" and "security".
The old proverb "Weeks of coding can save you hours of planning" does not apply here, at all.
Diaspora is about choice, not market share.
http://www.kickstarter.com/projects/196017994/diaspora-the-p...
At least, so says the FSF (and so do the IP lawyers I've talked to about it):
Is it better for the world for the open source community to fork left and right and ultimately risk fragmenting the market to fail to compete against facebook, or is it better for the open source community to work together as a singular voice and produce something spectacular?
I remain neutral in the answer, and I think Diaspora has a difficult path ahead of it.
It would be more interesting in my mind if the community actually worked together rather than forking to compete against Facebook. What if this was the opportunity for the open source community to rise up as a single voice and strike Facebook down? Afterall, we failed against Microsoft. Can we learn from our marketing and sales mistakes with Desktop Linux to strike a blow to closed source software? I don't know if it this project or some future project. I don't know if it is the slow march that will prevail. All I know is that the more we fragment, the easier we are to discount.
Well, I'm going to shave my beard now.
AGPL was written to address this exact issue. If it does not accomplish it (as is the case the original article is arguing for) then it's a problem with the license and not the Diaspora project.
It's alpha software. It's not perfect. They're not going to get everything right on the first go, be it software bugs or maybe-too-restrictive licensing. Let's give it more than 24 hours before declaring it 'dead.'
Wasn't that kinda the entire point of diaspora, to be open, this is really just the guys ensuring that it stays that way. Sure it sucks that you need to sign a contract but in order to maintain that it remains open, it needs to be restricted.
Yes i know how that sounds.
BSD licenses are great and all, but often lead to a situation where the original developers get used with little to no compensation in return in terms of code improvement or financial benefit. A great example of how annoying this can be to the original developers - look at the bottom paragraph of http://openssh.org/
My take on the whole thing - they should have published a spec, with hard and fast guidelines for interaction and preferably a protocol verification test suite, rather than code. Then release an implementation with a license that is GPL or proprietary or whatever - just make it so that 3rd parties can write interoperable code if they want.
To put this succinctly, we need the "HTTP" of social media, not the "Apache" of social media.
That is very deep and it applies to a LOT of different "markets," not just social networking. A truly open standard API for interoperability is a very different thing from a truly open standard implementation.
Society benefits, sure. Those who use the code benefit, yes. But the guys who initially develop the software get little back. Charity work should be for poor people.
Now add to that the Contributor Agreement, which assigns joint ownership to Diaspora, Inc. (who is free to license their work to other companies under any agreement of their choosing), compared to the contributors (who are bound by the AGPL).
So who's doing the charity work, and who are the parasites getting enriched here?
My post was really targeted at BSD style licenses and how they are awful.
The entire principle of pro bono work is as a civil service - improving society by engaging with the disadvantaged in your community.
Software professionals are still new to the professionalism thing. We haven't learned the lessons that lawyers and doctors learned a long time ago. Do pro bono work - it's an important part of life - but choose your beneficiaries wisely.
BSD licensed software is just handing free cash over to the advertising industry. Re-brand it, market it, make easy cash, and destroy the popularity of any GPL competitors which then stifles innovation for that particular type of product.
everyone may use and modify it, but has to disclose its modifications. (since its AGPL'ed)
contributions that find their way back into the parent project (dispora) must sign the contrib agreement so that diaspora can license it commercially under terms they pick. this allows them to potentially make some money selling commercial licenses. investors need this security because they do not want to invest in a product that everyone exploit equally.
i think the model is valid and fair. it work for the company i currently work for (zarafa.com).
jarin has the right to not like the license, sure. but if he used his patches to serve a diaspora instance from heroku to anyone besides him self he should (AGPL) disclose those patches. of course this does not mean he should sign the contrib agreement, but that would limit the impact of his work...
jarin calls diaspora dead. i think thats unfair. they did a great job and it will be nice reference material for a rails3+mongodb+haml+jquery+websocket project. good choise of technology in my eyes! (thank $DEITY for not going with php)
2. The "you give your contribution to us" clause is standard in any open source project. How, for example, will they be able to update the project license if they don't own the copyright?
2. That's not the problem. The problem is making developers sign a contract just to contribute to the project.
Fundraise for your own project and you can run it in any way you see fit.
Write the code yourself and you can license it in any way you see fit.
The Affero licensing prevents some commercial venture from using their code as a foundation, creating a hosted service, tacking on some proprietary candy that locks users in, and out-marketing them. I'm fine with them safeguarding against that.
1. They didn't "make" $200,000, they got $200,000 in donations, and yes, people should be allowed to accept donations. If you don't like the terms, don't donate. I'm sure the Diaspora guys would love it if someone put up another kickstarter page accepting donations towards contributing to the Diaspora code base.
The Linux kernel doesn't require copyright transfers. Most open source projects don't either (though many require a contributor license agreement).
The business of Diaspora is just as green as the code of Diaspora, and requiring copyright transfer is a very sensible way of anticipating the inevitable pivots.
When you can demonstrate to me how the existence of GPL-licensed web servers prevents the creation and sale of proprietary web servers, and additionally demonstrate to me that people will not pay other people to host stuff for them, I will accept that you "aren't allowed to" make money off of this.
Therefore, we have no need for huge, scalable seeds. And despite the AGPL, profitable companies can make money out of Diaspora: contribute => make the freedom box more attractive => sell more freedom boxes. Pure software companies can be paid by hardware companies to do this job, everyone's happy. Equating profitable with "proprietarizeable" is quite a stretch.
I feel like I'm stating the obvious, here. Could I be missing something?
Let me put it this way. Say you have a Facebook account. Say you use it as intended: by doing most of your (semi) private communication through it.
Now, how much would I have to pay you for you to surrender a copy of your Facebook account, with your wall, your past conversations, and a copy of what your friends let you see? Promise, I won't do anything bad, but please sign this little paper that let me to, just in case.
That's the real price of using Facebook. Either you really think your price is $0, or you didn't think this through (most people don't, which is why I think Facebook is so popular). My price is $you_can't_afford_it.
(Edit: I forgot to mention advertisements, but I don't know how much they really cost me.)
"It's open source" is not going to cut it for anyone but a subset of techies. Data portability probably won't be a big incentive for most people either, considering you can't even get them to back up their hard drives. Although I think it is a pretty cool idea (and I would like to have one), I have serious doubts that "you can pay us for a thing that you plug into your wall and your profile lives on it" will be much of a sales point for most people either.
(1) Diaspora does not ask you to surrender your data to anyone. You host it yourself. At home.
Now there's still the switching busyness. As far as I know, Diaspora is shall communicate with existing social networks, and of automatic import for your remote data. So, the transition really amounts to by the FreedomBox, plug it in, and push a few buttons. From there you feel no change, except for the eye candy.
No change, no cost. Sure, Zuck will still spy on you while your friends are still at Facebook, but as they move, he progressively won't be able to. The same mechanism can apply to gmail: when you move out, you can still send and receive emails, and you are spied by Google when you communicate with a gmail user (but only then). I glossed over encryption, but that's the idea.
(2) Well, you nailed it: convenience trumps everything. It's like the Maslow's hierarchy of needs, but for the "average consumer". Concrete and immediate needs, like convenience, are at the bottom. More abstract and remote needs, like freedom, are at the top. That's not how it should be, but I'm a bit guilty of this myself.
So, I agree that if the FreedomBox isn't as convenient as services on the cloud, it won't be used. I just believe that it can be. Heck it will even do automatic distributed backup. It could even do High Availability with your mail server (and your web servers if we manage to actually change HTTP to look up srv records).
Now, I reckon the FreedomBox is like Diaspora 2 months ago: vaporware. For now, we can only wait, see, and contribute. But I'm confident. An Iphone-like success in 2 years from now as predicted by Eben Moglen seems actually quite realistic.
Their biggest challenge however isn't code but rather getting the 500+ million people who don't care about private seeds to go through some clunky prohibitive process and start all over again. That's not to mention getting the millions of websites already building on top of FB to change.
OK that's a letdown.
The only problem I see here is site design - companies certainly won't like that their corporate style will be used freely. Hope this'll be worked around somehow (trademarking?)
About the code itself - Diaspora is a distributed system, so IMHO it's quite absurd to attract users with some proprietary installation-unique features. Diaspora is more of a network, not a product. Imagine some ISP creating their own proprietary extensions to the TCP procotol - sounds weird, right?
That doesn't follow. Anybody can take the AGPL'd codebase and make money off of it. It's not necessary to distribute something as closed source in order to make money, ya know.
That said, I hate the AGPL, simply because I disagree with trying to redefine "providing a service using Software X" as "distributing Software X." I'd have preferred to see them go with the plain old GPL, if they wanted a "viral" license. But whatever... it's their project.